The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,899
Mitigations16,068
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Custom Fields Account Registration For Woocommerce< 1.4
Unauthenticated Privilege Escalation vulnerability
9.8
2 minutes ago
Advanced Responsive Video Embedder10.8.7
Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter vulnerability
9.8
13 minutes ago
MemberGlut< 1.1.5
Unauthenticated Privilege Escalation to Administrator vulnerability
9.8
28 minutes ago
Printcart Web to Print Product Designer for WooCommerce< 2.5.3
Unauthenticated Arbitrary File Read and Server-Side Request Forgery vulnerability
8.6
34 minutes ago
MainWP Child< 6.1.2
Unauthenticated Administrator Authentication Bypass vulnerability
9.8
43 minutes ago
style-dictionary>= 4.3.0, < 5.4.4
Prototype Pollution in convertTokenData utility function
8.8
8 hours ago
@hypequery/clickhouse< 2.0.2
NPM: @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
9.8
9 hours ago
@nocobase/plugin-collection-sql< 2.0.62
NPM: NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
6.8
10 hours ago
qti-neon1.0.0
NPM: QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
8.6
14 hours ago
@novu/application-generic< 3.17.0
NPM: @novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
6.8
16 hours ago
@wakaru/cli>= 1.0.0, < 1.4.0
NPM: @wakaru/cli arbitrary file write during bundle unpack
7.1
16 hours ago
FundEngine<= 1.7.8
Broken Access Control vulnerability
6.5
2 days ago
Booking Calendar<= 11.4.2
Cross Site Scripting (XSS) vulnerability
7.1
2 days ago
RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg<= 1.5.1
Cross Site Scripting (XSS) vulnerability
6.5
2 days ago
Contact Form 7 – PayPal & Stripe Add-on< 2.5
Open Redirect vulnerability
4.7
2 days ago
Download Manager< 3.3.62
Unauthorized Protected File Download vulnerability
3.1
2 days ago
Smart Manager< 8.92.0
Contributor+ Stored XSS vulnerability
6.5
2 days ago
ChatBot< 8.5.2
Admin+ Second-Order SQL Injection vulnerability
3.8
2 days ago
The Events Calendar< 6.16.5.1
Unauthenticated Event Aggregator Import Status Manipulation vulnerability
5.3
2 days ago
Advanced Ads< 2.0.23
Contributor+ Stored XSS vulnerability
6.5
2 days ago